Description
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.
Remediation
References
http://www.securityfocus.com/bid/99930
https://bugzilla.redhat.com/show_bug.cgi?id=1474019
Related Vulnerabilities
CVE-2020-8910 Vulnerability in npm package google-closure-library
CVE-2021-35515 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.sentsin:layui
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-javalite